ethskills
Fail
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [DATA_EXPOSURE]: The skill provides a feedback mechanism in 'feedback/SKILL.md' that allows agents to send data to 'https://ethskills.com/api/feedback'. It includes instructions to scrub sensitive data and seek user consent before sending, although it also supports a pre-authorization token for automated reporting.
- [REMOTE_CODE_EXECUTION]: The 'noir/SKILL.md' file includes setup instructions for developer tools using the 'curl | bash' pattern for 'noirup' and 'bbup'. These are documented setup steps for legitimate developer toolchains.
- [COMMAND_EXECUTION]: The skill provides numerous shell commands for development workflows, project management, and QA in 'qa/SKILL.md' and 'frontend-playbook/SKILL.md', including 'grep', 'yarn', 'rm', and 'vercel'. These are intended for user-controlled local development tasks.
- [EXTERNAL_DOWNLOADS]: The skill dynamically fetches instruction and configuration files from 'ethskills.com' and 'raw.githubusercontent.com' to provide updated Ethereum knowledge (Ingestion points: 'SKILL.md', 'audit/SKILL.md'). Capability inventory includes local command execution and network requests, but the skill provides boundary markers instructing the agent to follow the content.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata